# StackRadar security

What StackRadar can touch, where your code goes, and what we still owe you.

## Access, scoped by you

A GitHub App with per-repo grants: read code, write branches and pull requests. It merges only when your required checks pass. Where reviews gate the merge, you add StackRadar to your ruleset’s bypass list yourself: one reviewed settings change, visible in the audit log, revocable any time. Uninstalling the App ends access on GitHub’s side.

## Your code stays yours

Agents read the paths a fix touches, in a per-run sandbox. The index they build dies with the sandbox. Model calls run under a zero-retention agreement with our model provider, and nothing trains on your code.

## Where data lives

StackRadar runs in EU regions of our infrastructure providers. The current subprocessor list sits in the DPA (https://stackradar.com/dpa/), and you can request it or subscribe to change notifications at any time.

## Nothing merges without your rules

Observe mode is the default. Policy lives in your repo as a committed file, every change passes your own CI, a soak window holds green changes short of the merge, and one click opens the revert PR.

## Certifications

We hold no SOC 2 or ISO 27001 today. Certification is on the roadmap, and this page will say so the day that changes. Until then: the DPA, the subprocessor list, and the permission scopes above are current.

## Report a problem

Found something? security@stackradar.com reaches people who can act on it. We read every report.
